Sirran
The Android, iPhone, Apple Watch, and Wear OS builds contain no advertising SDK, analytics SDK, or advertising-ID permission. Sirran Plus supports independent development; it does not remove advertising because advertising is absent for everyone.
Sirran is an independent product and is not an official application of,
affiliated with, or endorsed by Quran Foundation. On Android, Sirran's
optional online Quran reader uses the Quran Foundation Content
APIs to retrieve the Dar Al-Salam Center Turkish translation
(translations:210), Mishari Rashid al-‘Afasy ayah recitation
(recitations:7), and—only in an explicitly enabled build and
resolved Arabic reader—the user-selected Tafsir al-Muyassar
(tafsirs:16, ar-tafsir-muyassar) from the
Quran.com ecosystem.
QuranReflect is part of Quran
Foundation's wider ecosystem; Sirran does not access QuranReflect accounts,
private reflections, bookmarks, notes, reading history, or other Quran
Foundation user data.
Quran Foundation provided written authorization for the requested
commercial in-app use and long-term offline retention on 19 July 2026. On
30 July 2026, Quran Foundation expressly confirmed that Sirran may initialize
translations:210 and recitations:7 from the direct
snapshot endpoints, check Content Sync daily with the same resource filter,
and retain those resources on users' devices for the user-initiated in-app
offline experience. Production credentials remain provisioned only on
Sirran's server. Reader, synchronization, caching, and offline-download access
is available only in explicitly enabled Android builds and only after the
user's affirmative opt-in action. The backend uses the OAuth2
client_credentials flow for application access and does not
receive an end-user OAuth token. Public-content requests are keyed by content
resource rather than a user or device. On 6 August 2026 Quran Foundation
separately confirmed the identity, attribution and commercial/freemium
in-app display permission for the selected-ayah Tafsir al-Muyassar surface
without requiring a separate third-party licence.
Sirran's Production integration runs on Cloudflare Workers so Quran
Foundation credentials remain server-side and are never embedded in the app.
Ordinary reader and audio-delivery responses are marked
private, no-store. For the approved retained-content feature,
Sirran's backend stores integrity-validated public Quran-content bundles and
catalogue metadata for translations:210 and
recitations:7; this retained material is not linked to a Sirran
account, device identifier, reading history, bookmarks, notes, or worship
activity. Audio bytes are not retained in the backend content cache.
The Arabic tafsir path is distinct from that retained
translation/recitation flow. It runs only after affirmative QF consent, only
when the resolved reader language is Arabic, and only after the user selects
a specific ayah. The requested surah and ayah identifier and ordinary HTTPS
connection data pass through Sirran's server-side proxy; the tafsir response
is ephemeral and marked private, no-store. Sirran does not
prefetch, cache, download or retain the tafsir text, and does not create or
link it to an account, device identifier, reading history, bookmark, note,
subscription or advertising profile. The surface remains available
regardless of subscription status and contains no advertising, subscription
benefit or upsell. It is unavailable offline.
The source is Tafsir al-Muyassar (التفسير الميسر), prepared by a committee of scholars under the supervision of the King Fahd Glorious Quran Printing Complex. Quran Foundation requested one localized visible credit and clarified that it is not a formal licence condition. The Arabic-only surface uses التفسير الميسر — مجمع الملك فهد لطباعة المصحف الشريف; corresponding English documentation may use “Tafsir al-Muyassar — King Fahd Glorious Quran Printing Complex”. Sirran is independent and does not use Quran Foundation or Quran.com logos for this surface.
Sirran checks Quran Foundation Content Sync daily and applies reported updates, invalidations, and removals. After consent, Android may retain the approved Turkish translation and recitation catalogue in app-private, non-backed-up device storage. Audio is retained only after the user starts an in-app download. Approved content may remain usable while a device is offline for longer than seven days; when connectivity returns, Sirran synchronizes as soon as reasonably possible and applies relevant changes. Audio files cannot be exported or shared as standalone downloads or used outside Sirran. All Quran Foundation reading and recitation content remains available regardless of paid subscription status.
Sirran does not use end-user QF OAuth/OIDC, sign users into Quran Foundation accounts, or request user-data scopes. Any future QF account, bookmark, note, reflection, reading-history synchronization, or other user-data feature remains disabled until separately reviewed and disclosed.
Prayer preferences, reading or recitation history, notes, reflections, worship logs, tasbih counts, and similar data may reveal religious beliefs and can be sensitive personal data. Sirran keeps saved versions of these items on the device and does not create or retain a user-linked reading-history or worship profile on a publisher server. An opted-in QF public-content request transiently processes the requested resource identifier and ordinary connection data as described above. If a future feature needs publisher-server collection or synchronization of saved religious information, it will remain off until the user gives a separate, explicit, affirmative opt-in that is not bundled into general acceptance of the Terms of Use. Data will then be limited to the disclosed feature and purpose.
The Android implementation includes a separate consent screen that explains the requested content identifiers, ordinary connection data, app-private retention, user-started audio downloads, extended offline use, reconnection synchronization, and the prohibition on standalone export. The feature makes no QF request unless an explicitly enabled release switch, a safe proxy endpoint, and the user's affirmative opt-in are all active. The user can withdraw consent in Settings. Withdrawal stops future QF requests, cancels an active QF download, clears the consent state, and deletes downloaded or cached QF content from the device. The bundled Quran and unrelated local reading data remain available.
When you open Nearby Mosques, Sirran rounds the device coordinate to four decimal places (about 11 metres of latitude resolution) and sends it to public OpenStreetMap Overpass instances to find mosques progressively within 2 km, 5 km, and at most 10 km. Google Play classifies this four-decimal coordinate as Precise location, even though it is rounded. The app may try more than one public instance when a server is unavailable. This happens only when you use that feature. The publisher does not store the coordinate or the results on a server. On the phone, an in-process cache keeps the four-decimal coordinate key, search radius, result list, and cache time. A result is treated as fresh for 10 minutes and may be shown as explicitly stale after a network failure for up to 24 hours. This cache is not written to disk and disappears when the app process ends. There is no Sirran account. Tapping a result opens your maps app for directions.
The default calculation works locally. If you explicitly select an official timetable and confirm a supported place, Android sends only that public place identifier, the requested date range, and its time zone to the configured Sirran timetable adapter over HTTPS. It does not send your GNSS coordinate, prayer history, Quran activity, microphone audio, or an advertising identifier. Authority credentials are never embedded in the app. Hosting and network providers necessarily process connection data such as an IP address to deliver an internet response.
On Android, Google Play Billing is used to offer and restore Sirran Plus. Google handles account and payment information under its own terms. Sirran stores the resulting entitlement locally and does not receive or store your payment-card details. The current iPhone launch configuration has in-app purchases disabled and is submitted as a free app with no in-app purchases; StoreKit support in the code is inactive in that build.
Sirran does not disclose worship activity for advertising or unrelated profiling. The following services may receive only the information needed for the user-requested feature:
Where a provider processes personal data on Sirran's behalf, the corresponding feature will be enabled only with appropriate data-protection terms and instructions that prohibit unrelated use and misuse of Quranic content. Public endpoints that act independently are recipients/controllers under their own policies rather than Sirran subprocessors. Sirran does not send Quran Foundation user data to OpenStreetMap, Google, Apple, or GitHub for unrelated use. Any future QF account or user-data feature stays disabled until its additional legal, security, privacy, and Islamic-content protection controls have been verified.
The app uses the following only on your device, to provide its features:
.m4a file in the app's private local storage. You can play, manage, and delete these recordings from the library. They are not uploaded, synced, or sent to a third party.capturedAt), selected location/city, time zone, prayer method and madhab, tasbih label/count/target, remaining qada total, and active wird label/target. A Data Item is persistent until it is replaced or deleted and can be buffered while devices are disconnected. Google's Data Layer security overview and client-type reference state that only the same package signed with the same certificate can access the channel; direct Bluetooth uses standard Bluetooth encryption, and cloud-routed transfers are end-to-end encrypted. Google Play services may use Google-owned servers when Bluetooth is unavailable. Sirran does not operate a server for this sync.The Quran text in the app is "Tanzil Quran Text (Simple)" from the Tanzil
Project (tanzil.net), used under the Creative Commons Attribution 3.0 license
with in-app attribution. The bundled translation is "The Meaning of the
Glorious Koran" by Marmaduke Pickthall (1930, English), which is in the public
domain and shown with in-app attribution. No Turkish meal is packaged with the
app installation, so before the user enables and downloads the optional QF
content, offline reading uses the bundled Arabic Quran and bundled Pickthall
translation. Opening and reading this bundled corpus does not
make a network request. On Android, after affirmative consent, the user may
retain the Dar Al-Salam Center translations:210 meal and
user-selected recitations:7 audio for offline use through the
separate retained data flow described above. Tafsir al-Muyassar ID
16 is not bundled or retained; in an enabled Arabic reader it is
fetched only for a user-selected ayah through the ephemeral path described
above.
Sirran preserves Quran text unchanged, presents excerpts in context, and shows source attribution. QF content is not used for advertising profiles, biometric identification, or machine-learning training.
Sirran is not directed to children under 13. It does not ask for a date of birth, has no sign-up flow, and therefore cannot accept an underage account registration. It does not knowingly collect children's personal data. Parents and guardians should supervise a child's use of religious content and optional network features.
Sirran operates no first-party account or worship-history server. App settings (such as your selected city, madhab, and tasbih counts) are stored locally and are removed when you delete them in the app, clear app storage, or uninstall the app. The Nearby Mosques process cache has the 10-minute fresh/24-hour stale limits described above. Wear OS Data Items have Google Play services' persistent lifecycle described above and are overwritten when Sirran publishes newer state; they are not a publisher-server copy.
All Sirran-controlled network endpoints, including the deployed QF reader proxy, require HTTPS. QF credentials remain only in the server secret store and access is least-privilege. Production secrets must rotate at least every 90 days and immediately after suspected exposure. These controls are aligned with the QF Developer Privacy Packet's Security Rule 6.9. Sirran will begin responding to an actual or suspected API security incident in less than 24 hours and will report it to Quran Foundation no later than 24 hours after detection when QF systems or data may be affected.
The reader proxy does not add a Sirran user ID, device ID, advertising ID,
or reading-history identifier to QF requests. It processes the requested
resource identifier plus ordinary connection data such as IP address and
request time; any IP address/resource-identifier combination visible to the
infrastructure is handled by Cloudflare and Quran Foundation under their
published policies. Ordinary reader, tafsir and audio-delivery responses are
private, no-store. The selected-ayah tafsir body is not written
to Sirran's backend retained store or Android storage. Sirran's retained
backend store contains only
integrity-validated public Quran-content bundles and catalogue metadata; it
does not contain a QF user-data backup or reading-history profile. Approved
content stored on Android remains in app-private, non-backed-up storage until
the user deletes the relevant audio, withdraws consent, clears app storage,
or uninstalls Sirran. Sirran checks Content Sync daily, and a device that
reconnects applies relevant updates, invalidations, or removals as soon as
reasonably possible. If a future server feature stores user data, a verified
deletion request will hard-delete it from live systems within 30 days and
from backups within 90 days, unless a shorter legal period or lawful retention
duty applies. Other requests are handled under each recipient's published
retention and security practices.
You can deny or revoke optional operating-system permissions, disable optional features, delete feature data using the available in-app controls, clear app storage, or uninstall Sirran. Depending on applicable law, you may ask to access, correct, delete, restrict, object to, or obtain a copy of personal data controlled by the publisher. Send a verified request to the contact below; the publisher will respond within 30 days.
Sirran does not use end-user QF OAuth/OIDC or associate local data with a QF account. The backend application token is not an end-user token, so there is currently no user-granted Sirran QF token to revoke, and deleting a Quran Foundation account does not leave linked Sirran server data. End-user revocation controls, an OAuth revocation link, and an in-app server-data deletion mechanism will be added before any QF account/user-data integration ships.
Optional network providers may process ordinary connection data outside your country. Where Sirran selects a processor and cross-border transfer safeguards are legally required, Sirran will rely on the European Commission's Standard Contractual Clauses or an equivalent lawful mechanism and will comply with applicable local transfer laws. Independently operated public endpoints and app stores process data under their own policies and legal roles.
If the app's data practices change, this policy and relevant app-store disclosures will be updated before the change ships. The effective date above will change. Material changes will be announced through an in-app notice and, where the publisher has a user's contact address for a requested service, by email when appropriate.
Questions or privacy-rights requests:
See also the Sirran Terms of Use and Support page.